Device Information
System Model or SKU
AMD Ryzen AI Max 395
Please select one of the following
BIOS VERSION
03.05
Describe the bug
A clear and concise description of what the bug is.
Steps To Reproduce
Steps to reproduce the behavior:
$ fwupdmgr refresh --force && fwupdmgr get-updates && fwupdmgr update
Updating lvfs
Downloading… [ - ]
Successfully downloaded new metadata:
• 4 devices are updatable
• 3 devices are supported in the enabled remotes (an update has been published)
Devices with no available firmware updates:
• KEK CA
• Option ROM UEFI CA
• Windows UEFI CA
• frame.work-LaptopDB
• frame.work-LaptopKEK
• Hub
• WD BLACK SN7100 1TB
• WD BLACK SN7100 1TB
Devices with the latest available firmware version:
• UEFI CA
• System Firmware
Framework Desktop (AMD Ryzen AI Max 300 Series)
│
└─UEFI dbx:
│ Device ID: 362301da643102b9f38477387e2193e57abaa590
│ Summary: UEFI revocation database
│ Current version: 20250507
│ Minimum Version: 20250507
│ Vendor: Microsoft (UEFI:Microsoft)
│ Install Duration: 1 second
│ Update Error: Not enough efivarfs space, requested 30.7 kB and got 1.6 kB
│ GUIDs: f8ba2887-9411-5c36-9cee-88995bb39731 ← UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_X64
│ d07ff664-b0e1-5f4e-a723-d7fbcbfcb94f ← UEFI\CRT_3CD3F0309EDAE228767A976DD40D9F4AFFC4FBD5218F2E8CC3C9DD97E8AC6F9D&ARCH_X64
│ 69b2c147-9eaf-5793-a6fc-3d152320013c ← UEFI\CRT_80A010B8D42DDC03614704B050BBF9A43D3084CD0583D7829E7AE4F797DE6628&ARCH_X64
│ Device Flags: • Internal device
│ • Supported on remote server
│ • Needs a reboot after installation
│ • Device is usable for the duration of the update
│ • Updatable
│ • Only version upgrades are allowed
│ • Signed Payload
│ • Can tag for emulation
│
├─Secure Boot dbx Configuration Update:
│ New version: 20260402
│ Remote ID: lvfs
│ Release ID: 143971
│ Summary: UEFI Secure Boot Forbidden Signature Database
│ Variant: x64
│ License: Proprietary
│ Size: 24.6 kB
│ Created: 2025-09-02 00:00:00
│ Urgency: High
│ Tested: 2026-07-20 00:00:00
│ Distribution: rhel 10.0
│ Old version: 20160809
│ Version[fwupd]: 2.0.19
│ Vendor: Linux Foundation
│ Duration: 1 second
│ Release Flags: • Trusted metadata
│ • Is upgrade
│ Description:
│ This updates the list of forbidden signatures (the "dbx") to the latest release from Microsoft.
│
│ Some insecure bootloaders were added, due to security vulnerabilities that allowed an attacker to bypass UEFI Secure Boot. The additional entries were from:
│
│ • Baramanudi Management Suite
│ • EAZ EasyFix
│ • Finland Matriculation Examination Board
│ • NTC IT ROSA Linux
│ • PC-Doctor
│ • Spyrus WTGCreator
│ • WhiteCanyon blancco
│ • Some ancient shim releases for OpenSUSE, Oracle and Red Hat
│ Issues: 616257
│ CVE-2026-8863
│ Checksum: 9edea8bc287bf9bf4659856b28cf421f330eb2f658c163eab0a03512a98c0e78
│
└─Secure Boot dbx Configuration Update:
New version: 20250902
Remote ID: lvfs
Release ID: 130035
Summary: UEFI Secure Boot Forbidden Signature Database
Variant: x64
License: Proprietary
Size: 24.1 kB
Created: 2025-09-02 00:00:00
Urgency: High
Tested: 2026-07-06 00:00:00
Distribution: debian 13
Old version: 20250507
Version[fwupd]: 2.0.20
Tested: 2026-06-08 00:00:00
Distribution: ubuntu 26.04
Old version: 20230501
Version[fwupd]: 2.1.1
Tested: 2026-04-20 00:00:00
Distribution: ubuntu 25.10
Old version: 20230501
Version[fwupd]: 2.0.16
Tested: 2026-02-25 00:00:00
Distribution: ubuntu 25.10
Old version: 20230501
Version[fwupd]: 2.0.18
Tested: 2026-02-13 00:00:00
Distribution: ubuntu 25.10
Old version: 20230501
Version[fwupd]: 2.0.17
Tested: 2025-12-05 00:00:00
Distribution: fedora 42 (workstation)
Old version: 20250507
Version[fwupd]: 2.0.17
Tested: 2025-11-10 00:00:00
Distribution: fedora 43 (kde)
Old version: 20230501
Version[fwupd]: 2.0.16
Vendor: Linux Foundation
Duration: 1 second
Release Flags: • Trusted metadata
• Is upgrade
• Tested by trusted vendor
Description:
This updates the list of forbidden signatures (the "dbx") to the latest release from Microsoft.
Some insecure versions of the IGEL bootloader were added, due to a security vulnerability that allowed an attacker to bypass UEFI Secure Boot.
Issue: CVE-2025-47827
Checksum: 7178302fa23fcb875e7540900e299fb30a76758663efb7e1c56edc25cd3f316a
UEFI dbx is not currently updatable:
• Not enough efivarfs space, requested 30.7 kB and got 1.6 kB
Devices with the latest available firmware version:
• UEFI CA
• System Firmware
Devices with no available firmware updates:
• KEK CA
• Option ROM UEFI CA
• Windows UEFI CA
• frame.work-LaptopDB
• frame.work-LaptopKEK
• Hub
• WD BLACK SN7100 1TB
• WD BLACK SN7100 1TB
Operating System (please complete the following information):
Linux [hostname] 7.0.0-27-generic #27-Ubuntu SMP PREEMPT_DYNAMIC Thu Jun 18 19:13:49 UTC 2026 x86_64 GNU/Linux
Issue Description
Similar to #90, #235 , running fwupdmgr refresh --force && fwupdmgr get-updates && fwupdmgr update gives the error Not enough efivarfs space, requested 30.7 kB and got 1.6 kB
Device Information
System Model or SKU
AMD Ryzen AI Max 395
Please select one of the following
BIOS VERSION
03.05Describe the bug
A clear and concise description of what the bug is.
Steps To Reproduce
Steps to reproduce the behavior:
Operating System (please complete the following information):
Linux [hostname] 7.0.0-27-generic #27-Ubuntu SMP PREEMPT_DYNAMIC Thu Jun 18 19:13:49 UTC 2026 x86_64 GNU/Linux
Issue Description
Similar to #90, #235 , running
fwupdmgr refresh --force && fwupdmgr get-updates && fwupdmgr updategives the errorNot enough efivarfs space, requested 30.7 kB and got 1.6 kB